Vulnerability record · CVE-2020-8260 · published 28 October 2020
CVE-2020-8260: Pulse Connect Secure admin interface RCE via uncontrolled gzip extraction
Ivanti · Connect Secure
Pulse Connect Secure before 9.1R9 contains an uncontrolled gzip extraction flaw in its admin web interface, classified as unrestricted file upload (CWE-434). An attacker who already holds admin credentials can abuse the extraction process to write files and execute arbitrary code on the appliance. Because the device is a VPN gateway, compromise exposes a high-value foothold into the network.
Description
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with public exploit code and a very high EPSS score, but requires prior admin authentication, which limits the attacker pool.
What it is
Pulse Connect Secure before 9.1R9 contains an uncontrolled gzip extraction flaw in its admin web interface, classified as unrestricted file upload (CWE-434). An attacker who already holds admin credentials can abuse the extraction process to write files and execute arbitrary code on the appliance. Because the device is a VPN gateway, compromise exposes a high-value foothold into the network.
Impact
An authenticated administrator gains arbitrary code execution on the Pulse Connect Secure appliance, with high impact to confidentiality, integrity and availability. That yields control of a perimeter VPN device, enabling credential theft, traffic interception and lateral movement.
Attack surface
Reached over the network through the admin web interface (AV:N, PR:H, UI:N); the attacker must already be authenticated with administrative privileges. No user interaction is required.
Exploitation
Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS is very high (0.9648, 99.879th percentile). Public exploit code is referenced on Packet Storm, so exploitation is practical and observed.
What to do
- Upgrade Pulse Connect Secure to 9.1R9 or later per the vendor advisory (SA44601).
- Restrict admin web interface access to trusted management networks and disable it from untrusted exposure.
- Enforce strong, unique admin credentials and MFA, and rotate any credentials that may have been exposed.
- Monitor and audit admin accounts for unauthorized creation or privilege changes.
- If patching is delayed, isolate the appliance and inspect it for signs of compromise before returning it to service.
Detection
- Review admin web interface logs for unexpected file uploads or gzip archive handling activity.
- Hunt for new or modified files and unexpected processes on the Pulse Connect Secure appliance.
- Alert on admin logins from unusual source IPs or outside normal management windows.
- Correlate KEV/EPSS-driven scanning and exploitation attempts against the admin interface in network and web logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-8260 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Ivanti Pulse Connect Secure Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/160619/Pulse-Secure-VPN-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601 | Broken LinkVendor Advisory |
| http://packetstormsecurity.com/files/160619/Pulse-Secure-VPN-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601 | Broken LinkVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8260 | US Government Resource |
Track CVE-2020-8260 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8260), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.